Privacy policy
This Privacy Policy describes how WebinarForge (hereinafter "the Service") collects, uses and protects users' personal data. It complies with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and the amended French Data Protection Act.
1. Data controller
The data controller is Serge HOUNGBO, based in France, reachable at webinarforge@gmail.com.
The Data Protection Officer (DPO), Serge HOUNGBO, can be contacted at webinarforge@gmail.com for any question relating to the protection of your personal data.
2. Data collected
The Service collects the following categories of data:
- •Identification data: first name, last name, email address (when creating the account).
- •Project data: project name, niche, market analysis, target audience, pain points, offer, webinar sections, testimonials entered by the user.
- •Content data: texts, prompts and descriptions provided by the user to generate visuals, documents and presentations.
- •AI generation data: generation results (images, videos, PDF/PPTX documents, slides) stored in the user's account.
- •Subscription data: subscribed plan, billing cycle, credits used and remaining, transaction history (managed via Stripe).
- •Payment data: processed exclusively by Stripe. WebinarForge does not store bank card numbers.
- •Webinar registration data: name and email of registrants entered by the organizer for transmission to the emailing tool.
- •Integration data: Slack channel identifiers (when connecting the Slack integration).
- •File data: PDF/PPTX templates imported by the user (stored privately).
- •Browsing data: IP address, browser type, pages visited (for security and service improvement purposes).
3. Purposes and legal basis for processing
Your data is processed for the following purposes:
- •Creation and management of the user account (legal basis: performance of the contract, Art. 6 §1 b GDPR).
- •Provision of the Service: AI content generation, document creation, project management (performance of the contract).
- •Management of subscriptions and credits: billing, credit tracking, payment management via Stripe (performance of the contract).
- •Sending of transactional emails and reminders: registration confirmation, webinar reminders, replay delivery (performance of the contract and legitimate interest).
- •Improvement of the Service: usage analysis, abuse detection, performance optimization (legitimate interest, Art. 6 §1 f GDPR).
- •Slack notifications: launch alerts sent to the channel configured by the user (performance of the contract).
- •Security and fraud prevention: rate limiting, detection of suspicious activity (legitimate interest).
4. Processing by Artificial Intelligence
The Service uses generative artificial intelligence (language models, image generation, video generation) to produce content from the information entered by the user.
Accordingly, the data you enter (niche description, prompts, project texts) is transmitted to third-party AI providers (processors) for generation purposes. In accordance with the transparency obligations of Article 13 of the GDPR and the recommendations of the European AI Act, we inform you that:
- •Generated content (niche analyses, visuals, documents) is produced by AI models and constitutes a starting point to be validated by the user.
- •Data transmitted to AI providers is not used by WebinarForge to train models.
- •We recommend that you do not enter sensitive data (health, political opinions, biometric data, etc.) in the fields of the Service.
- •The user remains solely responsible for the generated content and its final use.
5. Recipients of the data
Your data is accessible to the following recipients:
- •WebinarForge (the Publisher), as data controller.
- •Base44 / Wix, as hosting provider and infrastructure supplier (processor).
- •Stripe, for payment processing and subscription management (processor, PCI-DSS Level 1 certified).
- •AI providers (language models, image generation, video generation) for content production (processors).
- •Slack (when the integration is enabled by the user) for sending notifications to the configured channel.
- •Emailing tools configured by the user (Mailchimp, SendGrid, Brevo, ActiveCampaign) for the transmission of webinar registrants.
- •Administrative and judicial authorities, upon duly justified legal request.
Your data is never sold to third parties for commercial purposes.
6. Transfers of data outside the EU
Some data may be processed by processors located outside the European Union (notably AI providers and the hosting provider). These transfers are governed by appropriate safeguards:
- •Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision (EU) 2021/914).
- •Additional technical and organizational measures (encryption in transit and at rest, pseudonymization).
- •Security certifications and standards (ISO 27001, SOC 2 Type II) held by the processors concerned.
7. Retention period
Your data is retained for the following periods:
- •Account data: retained for as long as the Service is used, then deleted within 30 days after the account deletion request (immediate deletion via the dedicated function in Settings).
- •Project data and generated content: retained as long as the account is active, deleted together with the account.
- •Subscription data and payment history: retained for the legal period of 10 years (accounting obligations, Article L.123-22 of the French Commercial Code).
- •Webinar registration data: retained as long as the project is active, deleted with the project.
- •Security logs and connection logs: retained for a maximum of 12 months (CNIL recommendation).
8. Data security
The Service implements appropriate technical and organizational measures to protect your data:
- •Encryption of data in transit (TLS 1.2/1.3) and at rest.
- •Data isolation per user (Row-Level Security): each user can only access their own projects and data.
- •Secure authentication with token-based session management.
- •Rate limiting to prevent abuse and brute-force attacks.
- •Regular backups and a business continuity plan.
- •Imported files (templates) stored privately, accessible only by the owner.
9. Cookies
The Service uses cookies and similar technologies strictly necessary for its operation (authentication session, language preferences, theme memorization). No advertising tracking or profiling cookies are set.
In accordance with Article 82 of the French Data Protection Act, you can configure your browser to refuse cookies, at the risk of some features being impaired.
10. Your rights (GDPR)
In accordance with the GDPR, you have the following rights over your data:
- •Right of access: obtain a copy of your personal data.
- •Right to rectification: correct inaccurate or incomplete data.
- •Right to erasure ("right to be forgotten"): request the deletion of your data.
- •Right to restriction of processing: request the temporary suspension of processing.
- •Right to data portability: receive your data in a structured and reusable format.
- •Right to object: object to processing on legitimate grounds.
- •Right to withdraw your consent at any time (where processing is based on consent).
- •Right to lodge a complaint with the CNIL (www.cnil.fr/fr/plaintes).
To exercise these rights, you can use the account management functions built into the Service (account deletion in Settings) or contact webinarforge@gmail.com. The Publisher undertakes to respond within one month, in accordance with Article 12 of the GDPR.
11. Processors
The Service relies on the following processors to provide its features:
- •Base44 / Wix: hosting, database, cloud infrastructure, SDK.
- •Stripe: payment processing and subscription management.
- •AI providers: text generation (LLM), image generation, video generation, audio transcription.
- •Slack: launch notifications (when the integration is enabled).
- •Emailing providers (chosen by the user): Mailchimp, SendGrid, Brevo, ActiveCampaign.
Each of these processors is bound to the Publisher by a contract governing data processing in accordance with Article 28 of the GDPR.
